Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5841

Опубликовано: 01 фев. 2024
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия до 3.2.1 (включая)

EPSS

Процентиль: 73%
0.00804
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 2 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
redhat
почти 2 года назад

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVSS3: 9.1
debian
почти 2 года назад

Due to a failure in validating the number of scanline samples of a Ope ...

rocky
12 месяцев назад

Important: openexr security update

rocky
около 1 года назад

Important: openexr security update

EPSS

Процентиль: 73%
0.00804
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-122
CWE-787